Does EU AI Act require Transparency & Disclosure?

European Union • phased enforcement

Yes — 2 provisions

Requirements at a glance

This regulation imposes 20 specific requirements for Transparency & Disclosure across 2 provisions:

Transparency Disclosure (Article 50)

Copy link to this provision

Obligation:
Transparency
phased enforcement
Effective:
Aug 2, 2026
Risk tier:
limited-risk
Scope:
Providers of systems intended to interact directly with natural persons and of systems generating synthetic audio, image, video or text (Article 50(1)-(2)); deployers of emotion recognition or biometric categorisation systems, systems producing deepfakes, and systems generating or manipulating text published to inform the public on matters of public interest (Article 50(3)-(4))
high-impactcross-domain
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02. The Commission published Article 50 scope guidelines on July 20, 2026. The final Code of Practice on Transparency of AI-generated Content was published on June 10, 2026; the Commission concluded its adequacy assessment on July 8. The code is voluntary and supports implementation of Article 50(2), (4) and (5). It does not replace the Act or the guidelines, and adherence is not conclusive evidence of compliance. These implementation materials do not postpone the statutory application date or remove the Article 111(4) transitional condition.

Requirements

RequirementDetails
Interaction disclosureProviders must design systems intended to interact directly with natural persons so those persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Article 50(1))
Synthetic content markingProviders of systems, including general-purpose AI systems, generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, taking into account content-specific limitations, implementation costs and the generally acknowledged state of the art (Article 50(2))
Emotion recognition and biometric categorisation noticeDeployers must inform natural persons exposed to emotion recognition or biometric categorisation systems of their operation (Article 50(3))
Deepfake disclosureDeployers generating or manipulating image, audio or video constituting a deepfake must disclose that the content is artificially generated or manipulated (Article 50(4))
Public-interest text disclosureDeployers of systems generating or manipulating text published to inform the public on matters of public interest must disclose its artificial generation or manipulation. This does not apply where the use is authorised for specified criminal-law purposes, or where human review or editorial control occurs and a natural or legal person holds editorial responsibility (Article 50(4))
Disclosure timing and accessibilityInformation under Article 50(1)-(4) must be clear and distinguishable, provided by the first interaction or exposure, and conform to applicable accessibility requirements (Article 50(5))
Disclosure exceptionsArticle 50(1) excepts certain law-authorised criminal-law systems unless available for public crime reporting; Article 50(2) excepts limited assistive editing or insubstantial changes and certain law-authorised criminal-law uses; Article 50(3) excepts certain permitted criminal-law uses. Article 50(4) excepts law-authorised criminal-law uses; for deepfakes forming part of an evidently artistic, creative, satirical, fictional or analogous work or programme, disclosure remains required but is limited to an appropriate statement of the existence of generated or manipulated content that does not hamper the work's display or enjoyment (Article 50(1)-(4))
Generative AI grace periodProviders of systems, including general-purpose AI systems, generating synthetic audio, image, video or text that were placed on the market before 2026-08-02 must take the necessary steps to comply with Article 50(2) by 2026-12-02. This transition concerns Article 50(2), not the other disclosure duties (Article 111(4), inserted by Regulation (EU) 2026/1744)
Marking codes of practiceThe Commission facilitates Union-level codes of practice for detection, marking and labelling of AI-generated or manipulated content, assesses their adequacy for Article 50(2) and (4), and may impose common rules by implementing act if a code is inadequate (Article 50(7), as replaced by Regulation (EU) 2026/1744)

Penalties

ViolationFine
Transparency non-compliance (Article 50)Up to EUR 15M or, for an undertaking, 3% of its preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC ceilings (Article 99(4)(g))
Incorrect, incomplete or misleading information in response to a request from a notified body or national competent authorityUp to EUR 7.5M or, for an undertaking, 1% of its preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC ceilings (Article 99(5))
SME ceilingFor SMEs, including start-ups, each fine under Article 99(3)-(5) is capped at the lower of the percentage or fixed amount (Article 99(6))
SMC ceilingFor small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)

High-Risk Transparency and Instructions for Use (Article 13)

Copy link to this provision

Obligation:
Transparency
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems. The duty runs to the instructions for use supplied to deployers, not to end users. Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products
upcominghigh-impact
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.

Requirements

RequirementDetails
Operational transparencyHigh-risk systems must be designed and developed so their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately (Article 13(1))
Instructions for useHigh-risk systems must be accompanied by instructions for use in an appropriate digital format or otherwise, containing concise, complete, correct and clear information relevant, accessible and comprehensible to deployers (Article 13(2))
Provider identityInstructions must state the identity and contact details of the provider and, where applicable, its authorised representative (Article 13(3)(a))
Capabilities and limitationsInstructions must state intended purpose, the accuracy, robustness and cybersecurity metrics the system was validated against, foreseeable circumstances affecting those levels, and risks arising under intended use or reasonably foreseeable misuse (Article 13(3)(b))
Explainability informationWhere applicable, instructions must describe technical capabilities to provide information explaining the system's output (Article 13(3)(b)(iv))
Group performance and input dataWhere appropriate, instructions must state performance regarding specific persons or groups, and input-data specifications or relevant information about training, validation and testing datasets (Article 13(3)(b)(v)-(vi))
Output interpretationWhere applicable, instructions must provide information enabling deployers to interpret the system's output and use it appropriately (Article 13(3)(b)(vii))
Human oversight measuresInstructions must describe the human oversight measures built in under Article 14, including technical measures facilitating output interpretation by deployers (Article 13(3)(d))
Pre-determined changesWhere applicable, instructions must describe the changes to the system and its performance which the provider pre-determined at the moment of the initial conformity assessment (Article 13(3)(c))
Resources, lifetime and maintenanceInstructions must state computational and hardware resources needed, expected lifetime, and any necessary maintenance and care measures, including their frequency and software updates (Article 13(3)(e))
Logging mechanismsWhere relevant, instructions must describe mechanisms enabling deployers to collect, store and interpret logs under Article 12 (Article 13(3)(f))

Penalties

ViolationFine
Provider non-compliance through Article 16(a)Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.
Incorrect, incomplete or misleading information supplied to notified bodies or national competent authorities in reply to a requestUp to EUR 7.5 million; for undertakings, up to 1% of total worldwide annual turnover for the preceding financial year or EUR 7.5 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(5), (6), and (6a))
View full regulation View obligation Obligation matrix